Unifi Network Application
Vendor:
First CVE: Jul 1, 2023 · Active for 3 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Unifi Network Application over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2023
3 years ago
Most Recent CVE
Jul 2, 2026
23 days ago
CVE Severity & Scoring
Unifi Network Application9 CVEs
22%
67%
11%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low4 (44.4%)
High3 (33.3%)
None2 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55114HIGH A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges wit | Jul 2, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-55118HIGH A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application t | Jul 2, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-54406HIGH A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalat | Jul 2, 2026 | 8.7 | 37 | NO | NO |
CVE-2026-56842HIGH A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privi | Jul 2, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-54405HIGH A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack | Jul 2, 2026 | 7.5 | 33 | NO | NO |
CVE-2023-28365CRITICAL A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious comma | Jul 1, 2023 | 9.1 | 26 | NO | NO |
CVE-2024-42025HIGH A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with uni | Sep 13, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-41721MEDIUM Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access contr | Oct 25, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-32000MEDIUM A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges b | Jul 8, 2023 | 4.8 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Unifi Network Application
Top CWEs
Versions
No cataloged versions.